GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
39
GitHub Actions
38
Go
2,750
Maven
5,000+
npm
4,353
NuGet
765
pip
4,114
Pub
12
RubyGems
960
Rust
1,069
Swift
45
Unreviewed advisories
All unreviewed
5,000+
305,636 advisories
Filter by severity
MineAdmin has an insecure default password
Critical
CVE-2025-65854
was published
for
mineadmin/mineadmin
(Composer)
Dec 12, 2025
Liferay Portal and DXP Instance Admin can execute code using Objects Actions and Validations
High
CVE-2025-3586
was published
for
com.liferay:com.liferay.object.service
(Maven)
Dec 12, 2025
aircompressor Snappy and LZ4 Java-based decompressor implementation can leak information from reused output buffer
High
CVE-2025-67721
was published
for
io.airlift:aircompressor-v3
(Maven)
Dec 12, 2025
Ruby-saml has a SAML authentication bypass due to namespace handling (parser differential)
Critical
CVE-2025-66567
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Ruby-saml allows a Libxml2 Canonicalization error to bypass Digest/Signature validation
Critical
CVE-2025-66568
was published
for
ruby-saml
(RubyGems)
Dec 8, 2025
Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule
High
CVE-2025-67750
was published
for
lightning-flow-scanner
(npm)
Dec 12, 2025
Apache StreamPark uses a Weak Encryption Algorithm
High
CVE-2025-54981
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
Apache StreamPark has a hard-coded encryption key
High
CVE-2025-54947
was published
for
org.apache.streampark:streampark
(Maven)
Dec 12, 2025
jshERP versions 3.5 and earlier are affected by a stored XSS vulnerability. This vulnerability...
Moderate
Unreviewed
CVE-2025-67341
was published
Dec 12, 2025
Nextcloud Server 30.0.0 is vulnerable to an Insecure Direct Object Reference (IDOR) in the /core...
Moderate
Unreviewed
CVE-2025-64011
was published
Dec 12, 2025
RuoYi versions 4.8.1 and earlier is affected by a stored XSS vulnerability in the /system/menu...
Moderate
Unreviewed
CVE-2025-67342
was published
Dec 12, 2025
Use after free in Password Manager in Google Chrome prior to 143.0.7499.110 allowed a remote...
Moderate
Unreviewed
CVE-2025-14372
was published
Dec 12, 2025
Plesk 18.0 has Incorrect Access Control.
Critical
Unreviewed
CVE-2025-66430
was published
Dec 12, 2025
jshERP v3.5 and earlier is affected by a stored Cross Site Scripting (XSS) vulnerability via the ...
Moderate
Unreviewed
CVE-2025-67344
was published
Dec 12, 2025
HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php...
Moderate
Unreviewed
CVE-2025-55816
was published
Dec 11, 2025
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_core: Disable...
Moderate
Unreviewed
CVE-2024-58241
was published
Sep 24, 2025
In the Linux kernel, the following vulnerability has been resolved:
wifi: brcmfmac: fix use...
High
Unreviewed
CVE-2025-39863
was published
Sep 22, 2025
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: l2cap: Check...
Moderate
Unreviewed
CVE-2025-39889
was published
Sep 24, 2025
In the Linux kernel, the following vulnerability has been resolved:
bpf: Tell memcg to use...
Moderate
Unreviewed
CVE-2025-39886
was published
Sep 23, 2025
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath12k: fix memory...
Moderate
Unreviewed
CVE-2025-39890
was published
Sep 24, 2025
In the Linux kernel, the following vulnerability has been resolved:
accel/ivpu: Prevent recovery...
High
Unreviewed
CVE-2025-39896
was published
Oct 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
mm/userfaultfd: fix...
Moderate
Unreviewed
CVE-2025-39899
was published
Oct 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
net_sched: gen_estimator:...
Moderate
Unreviewed
CVE-2025-39900
was published
Oct 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
net: xilinx: axienet: Add...
Moderate
Unreviewed
CVE-2025-39897
was published
Oct 1, 2025
In the Linux kernel, the following vulnerability has been resolved:
net: phylink: add lock for...
High
Unreviewed
CVE-2025-39905
was published
Oct 1, 2025
ProTip!
Advisories are also available from the
GraphQL API